ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-4878
A flaw was found in libcap.

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.

NVD description · AI analysis pending
7.0<1% PoC
  • libcap project libcap
  • libcap project openshift container platform
  • libcap project enterprise linux
CVE-2023-2603
+1 in the same advisory: …2602
A vulnerability was found in libcap.

A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.

NVD description · AI analysis pending
7.8
group max
<1% PoC
  • libcap project libcap
  • libcap project enterprise linux
  • libcap project fedora
  • +1 more